Dashboard › craft › tar-fs pinned at 1.16.6 via override (t…
019fdd1b-e164-7bec-ae67-53b567a18e63craft pins tar-fs at 1.16.6 via root pnpm override tar-fs@<1.16.4: 1.16.6 because @vercel/client exact-pins vulnerable 1.16.3 (GHSA-pq67-2wwv-3xjx / CVE-2024-12905 link-following + path traversal, GHSA-8cj5-5rvv-wf4v, GHSA-vj76-c3g6-qr5v). 1.16.6 (latest patched 1.x) keeps the tar-stream@1.x dependency tree; jumping to 2.x would switch tar-stream from 1.x to 2.x. In craft's usage the vulnerability is unreachable — @vercel/client only calls pack() (archive.js createTgzFiles); the advisories are in extract — but dependency-review gates the merge anyway. Verified via npm audit API: 1.16.4 and 1.16.6 report 'advisories: none'.